Executive Summary
GRIFFON is a JavaScript backdoor employed by the FIN7 group, designed to execute commands from browsers and exfiltrate data during targeted financial attacks. It operates covertly via malicious scripts embedded in phishing emails or compromised webpages, providing attackers with persistent access across corporate networks. Key capabilities include remote code execution within web contexts, credential harvesting, and clandestine communication with C2 servers. Detection requires attentive monitoring of anomalous JavaScript activity and outbound traffic from browsers.
Enhanced Description
GRIFFON is a JavaScript-based backdoor that has been linked to the financially motivated cyber‑criminal group FIN7, as reported by SecureList in May 2019. The malware operates by embedding malicious JavaScript into compromised web pages or phishing emails, enabling attackers to execute arbitrary commands and exfiltrate sensitive information from victims’ browsers. While detailed technical analysis of GRIFFON is limited, the available evidence indicates that it leverages client‑side scripting to bypass typical security controls and maintain persistence through repeated execution in corporate network environments. FIN7 is known for executing sophisticated multi‑stage attacks against financial institutions, combining phishing, credential theft, and lateral movement with a suite of custom malware families. GRIFFON fits within this strategy by providing an unobtrusive foothold that can be used to harvest credentials, navigate internal networks, or download additional payloads. The use of JavaScript affords the attackers flexibility in targeting, allowing them to manipulate browser sessions, hook network requests, and stealthily communicate with command‑and‑control (C2) infrastructure. The impact of GRIFFON is primarily financial: it enables FIN7 to compromise banking software, siphon customer data, and facilitate large‑scale fraud operations. Because the malware runs within a browser’s scripting engine, traditional endpoint protection often fails to detect it unless specifically configured for script analysis or network anomaly monitoring. Overall, GRIFFON exemplifies how FIN7 combines low‑profile client‑side techniques with high‑value targets. Organizations exposed to phishing campaigns or compromised web content should treat any suspicious JavaScript injection as a potential backdoor threat and implement layered defenses accordingly.
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
The data is derived from a single publicly available SecureList article, limiting depth of technical insight. Key gaps include unknown persistence mechanisms, detailed command & control architecture, and evidence of lateral movement. Confidence in the broad threat profile remains high, but specifics about exploitation steps and payloads are uncertain.
GRIFFON is a JavaScript backdoor used by FIN7. (Citation: SecureList Griffon May 2019)